Live data from Hacker News

Yahoo Hacked

webcache.googleusercontent.com

21–30 of 258 posts

Re: Yahoo Hacked

#21
This writeup doesn't really get to the point so, the tl;dr

He was looking for places to exploit shellshock by googling for cgi scripts. Most of the ones he did find had already been hit by someone using a perl script that made them join an irc channel that was being used as CnC. He also joined it and monitored it. A bunch of different yahoo boxes were in the channel and he saw some of them get rooted.

Re: Yahoo Hacked

#23

This guy works in the security industry and yet he couldn't google "yahoo security" to find their security contact email address (second result for me)? He was also unaware that Yahoo runs a Bug Bounty Program?

Well.. you didn't read the first couple lines? Notably:

> I’ve notified both Yahoo! and the FBI New Orleans field office of the infiltration, but in my eyes, they really aren’t seeing the severity and danger of this situation, and really are not reacting quick enough.

> This document is being released due to several high profile companies being infiltrated using the recent Shellshock vulnerability, and what I have deemed as an improper response, or lack thereof ...

Seems pretty straight forward: hackers have already downloaded all the personal data out of these organizations and are probably using it in ways harmful to the general public already. This guy is forgoing his probable bug bounty payouts as this is, as he says, a really serious issue.

Thank you to him!

Re: Yahoo Hacked

#24

This guy works in the security industry and yet he couldn't google "yahoo security" to find their security contact email address (second result for me)? He was also unaware that Yahoo runs a Bug Bounty Program?

Then he wouldn't bring attention to his consultancy firm. "Gee, these guys sure did show the Yahoo CEO! We need to hire them!" Says the MBA.

Re: Yahoo Hacked

#26
Am I the only one that thinks this kind of thing would be cool to see? I've seen logs of attacks, but I've never watched a botnet irc live. that would be crazy for me. Not really moving the conversation forward, but is this so commonplace that I'm the odd man for marveling?

Re: Yahoo Hacked

#27

This guy works in the security industry and yet he couldn't google "yahoo security" to find their security contact email address (second result for me)? He was also unaware that Yahoo runs a Bug Bounty Program?

According to this[1] article about the current issue:

"Before releasing this information, Hall emailed Yahoo and tweeted at its engineering team and CEO Marissa Mayer.

It was confirmed to him that its servers had been infiltrated but Yahoo refused to pay him for alerting them as it was not part of the company’s bug bounty programme."

[1]: http://www.independent.co.uk/life-style/gadgets-and-tech/new...

EDIT: The quote previously included "Yahoo is notorious for its disregard of bug bounty hunters, having last year rewarded one such hacker who identified three bugs in Yahoo's servers with a $25 voucher for company merchandise." but I moved it here as it caused confusion regarding which issue the article was referencing.

Re: Yahoo Hacked

#28
post #13

Is this a new phenomenon? I always felt that Yahoo's systems weren't secure. Until I shut down my Yahoo accounts, it would be a semi-regular occurrence for both my Yahoo email and IM to send out spam to everyone in my Yahoo contacts list. Am I wrong? I've since shut down my account since I got sick of dealing with it.

That's not a Yahoo hack though. When that happens it is almost always your local machine that has been breached by a virus which simply reads the locally stored contact list. And to answer your question, no, it is not a regular occurrence for Yahoo, or any of the major players, to have their servers hacked.

A number of times in recent memory Yahoo has been subject to attacks using XSS and similar. One example of one that was exploited (there was a disclosure back in May, but that didn't have reports of active exploits): http://thenextweb.com/insider/2013/01/31/yahoo-mail-users-st...

Re: Yahoo Hacked

#29
post #13

Earlier quoted context omitted.

That's not a Yahoo hack though. When that happens it is almost always your local machine that has been breached by a virus which simply reads the locally stored contact list. And to answer your question, no, it is not a regular occurrence for Yahoo, or any of the major players, to have their servers hacked.

To my knowledge, my machine is secure. It wasn't Windows and I had both anti-virus and a firewall active. For one thing, what made this strange was that I haven't even logged into Yahoo for months (probably close to a year) when this happened, repeatedly.

Another possible explanation is password reuse on a site that was breached.

Re: Yahoo Hacked

#30
Frick. A .pl CGI script on a production box?

All the yapache & yphp security fixes and is all undone by a a .pl with +ExeCGI.

They used to run "crack days" where all of us used to get kicks out of breaking & entering prod, whatever means available.

Was a fun way to weed through such low-hanging issues, by a highly motivated (i.e otherwise bored) crowd.

I wonder if they still have them.

Post reply on HN